I emailed Fortinet with this same question, their reponse: The best way
to accomplish this would be to create an IPsec tunnel between the Azure
gateway in each VNET and the FortiGate itself. In this way, each VNET
could connect on a unique VPN port o...